PulseAugur
实时 22:20:59
English(EN) CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()

AWS Postgres MCP 服务器漏洞已在 1.1.7 版本中修复

AWS Labs 的 Postgres MCP 服务器中发现了一个安全漏洞,标识为 CVE-2026-85787。该漏洞源于 `mutable_sql_detector.py` 脚本中不完整的关键字阻止列表,允许 SQL 命令绕过只读配置。这可能使攻击者即使在服务器设置为只读时也能修改数据或更改会话状态。AWS 已发布补丁,1.1.7 及更高版本通过加强阻止列表和添加特定模式块来解决此问题。 AI

影响 缓解了 AWS Labs Postgres MCP 服务器用户的特定安全风险,防止了未经授权的数据修改。

排序理由 特定软件包的安全补丁,而非核心 AI 模型发布。

在 dev.to — MCP tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

AWS Postgres MCP 服务器漏洞已在 1.1.7 版本中修复

本文如何被排名

Signal score
15 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
特定软件包的安全补丁,而非核心 AI 模型发布。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
Standard
On-topic for AI-industry coverage; kept in the public index.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Michael Kantor ·

    CVE-2026-85787:AWS postgres MCP 只读拒绝列表遗漏 set_config()

    <p><em>Originally published at <a href="https://hol.org/blog/cve-2026-85787-awslabs-postgres-mcp-sql-denylist-bypass" rel="noopener noreferrer">HOL</a></em></p> <p><strong>Read-only mode on AWS Labs' Postgres MCP server was enforced by a keyword denylist that missed several Postg…